input-filtering

1 article
sort: new top best
clear filter
0 6/10

A stored XSS vulnerability bypassed input filters by injecting malicious HTML attributes into an input field. The attacker circumvented tag filtering and character encoding by using OnMouseOver event handlers with backtick-quoted function calls to execute JavaScript via user interaction.

Prial Islam Khan
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details